時価総額: $2.2026T 0.80%
ボリューム(24時間): $38.3583B -35.30%
  • 時価総額: $2.2026T 0.80%
  • ボリューム(24時間): $38.3583B -35.30%
  • 恐怖と貪欲の指数:
  • 時価総額: $2.2026T 0.80%
暗号
トピック
暗号化
ニュース
暗号造園
動画
トップニュース
暗号
トピック
暗号化
ニュース
暗号造園
動画
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

暗号通貨のニュース記事

中国人トレーダー、バイナンスのハッキング詐欺で100万ドル損失

2024/06/04 05:20

中国人トレーダーは、Aggr と呼ばれる Google Chrome のプロモーション プラグインを使ったハッキン​​グ詐欺の被害に遭い、100 万ドルを失いました。

中国人トレーダー、バイナンスのハッキング詐欺で100万ドル損失

A Chinese cryptocurrency trader has lost $1 million in a hacking scam perpetrated through a promotional Google Chrome plugin called Aggr. The plugin reportedly stole cookies from users, enabling hackers to bypass password and two-factor authentication (2FA) verification to access the victim’s Binance account.

中国の仮想通貨トレーダーが、Aggr と呼ばれる Google Chrome のプロモーション プラグインを介したハッキン​​グ詐欺で 100 万ドルの損失を被りました。このプラグインはユーザーから Cookie を盗み、ハッカーがパスワードと 2 要素認証 (2FA) 検証をバイパスして被害者の Binance アカウントにアクセスできるようにしたと報告されています。

The trader, who goes by the handle CryptoNakamao on social media platform X, recounted the incident, which occurred on May 24. He noticed unusual trading activity in his Binance account after checking the Bitcoin price on the Binance app. By the time he sought assistance, the hacker had already withdrawn all the funds.

ソーシャルメディアプラットフォームXでハンドルネームCryptonakamaoとして活動するこのトレーダーは、5月24日に起こった事件について詳しく語った。彼は、Binanceアプリでビットコインの価格をチェックした後、自分のBinanceアカウントで異常な取引活動が行われていることに気づいた。彼が支援を求めたときには、ハッカーはすでにすべての資金を引き出していました。

The trader claimed that the hackers accessed his web browser cookie data through the Aggr Chrome plugin. He had installed the plugin to gain insights from prominent traders, unaware that it was designed to steal browsing data and cookies. The hackers used the stolen cookies to hijack active user sessions without needing passwords or authentication, enabling them to carry out multiple leveraged trades and profit by manipulating low liquidity trading pairs.

このトレーダーは、ハッカーが Aggr Chrome プラグインを通じて彼の Web ブラウザの Cookie データにアクセスしたと主張しました。彼は、このプラグインが閲覧データと Cookie を盗むように設計されているとは知らずに、著名なトレーダーから洞察を得るためにこのプラグインをインストールしていました。ハッカーは盗んだ Cookie を使用して、パスワードや認証を必要とせずにアクティブなユーザー セッションをハイジャックし、複数のレバレッジ取引を実行し、流動性の低い取引ペアを操作して利益を得ることができるようにしました。

Despite the hacker's inability to directly withdraw funds due to 2FA, they used the cookies and active login sessions to execute trades. The hacker bought several tokens in the Tether (USDT) trading pair with high liquidity and placed limit sell orders at inflated prices in Bitcoin (BTC), USD Coin (USDC), and other low liquidity trading pairs. They then opened leveraged positions, bought large amounts, and completed cross-trading. Cross-trading involves offsetting buy and sell orders for the same asset without recording the trade on the exchange.

ハッカーは 2FA により資金を直接引き出すことができなかったにもかかわらず、Cookie とアクティブなログイン セッションを使用して取引を実行しました。ハッカーは流動性の高いテザー (USDT) 取引ペアでいくつかのトークンを購入し、ビットコイン (BTC)、USD コイン (USDC)、およびその他の流動性の低い取引ペアにつり上げられた価格で指値売り注文を出しました。その後、レバレッジを利かせたポジションを開設し、大量に購入し、クロス取引を完了しました。クロス取引には、取引所での取引を記録せずに、同じ資産の買い注文と売り注文を相殺することが含まれます。

Accusations Against Binance

バイナンスに対する告発

The trader accused Binance of failing to implement necessary security measures despite the unusually high trading activity on his account. He also claimed that the exchange did not take timely action even after he reported the issue. According to the trader, Binance was aware of the fraudulent plugin and was conducting an internal investigation but did not inform users or take preventive measures.

このトレーダーは、彼のアカウントでの取引活動が異常に活発であるにもかかわらず、必要なセキュリティ対策を講じていないとしてバイナンスを非難した。同氏はまた、問題を報告した後も取引所はタイムリーな措置を講じなかったと主張した。このトレーダーによると、バイナンスは不正なプラグインを認識しており、内部調査を行っていたが、ユーザーへの通知や予防策は講じていなかったという。

“Binance did nothing even though it knew of the theft and frequent cross-trading. Hackers manipulated accounts for over an hour, causing extremely abnormal transactions in multiple currency pairs without any risk control; Binance failed to freeze the funds of the obvious hacker’s single account on the platform in time,” the trader wrote.

「バイナンスは、盗難と頻繁な相互取引を知っていたにもかかわらず、何もしませんでした。ハッカーは 1 時間以上にわたってアカウントを操作し、リスク管理なしで複数の通貨ペアで極めて異常な取引を引き起こしました。バイナンスはプラットフォーム上の明らかなハッカーの単一アカウントの資金を期限までに凍結できなかった」とトレーダーは書いた。

Binance’s Response

バイナンスの対応

Yi He, co-founder of Binance, refuted CryptoNakamao's claims and clarified the situation on social media, stating, “Look closely; this user's account was breached because their own computer was hacked; they are a lost cause. After the hack, the hacker could not withdraw funds, so the hacker sold the victim’s coins, which led to trading losses.”

バイナンスの共同創設者イー・ヘ氏はクリプトナカマオ氏の主張に反論し、ソーシャルメディアで状況を明らかにし、次のように述べた。このユーザーのアカウントは、自分のコンピューターがハッキングされたために侵害されました。それらは失われた大義です。ハッキング後、ハッカーは資金を引き出すことができなかったため、ハッカーは被害者のコインを売却し、取引損失につながりました。」

“We sympathize with your experience, but according to the information we have learned so far, the reason for your asset loss is that your related devices were manipulated because of the installation of malicious plug-ins. Unfortunately, we have no way to compensate for such cases that have nothing to do with Binance,” the exchange stated.

「私たちはあなたの経験に同情しますが、これまでに得た情報によると、あなたの資産損失の理由は、悪意のあるプラグインのインストールにより関連デバイスが操作されたことです。残念ながら、バイナンスとは関係のないそのようなケースを補償する方法はありません」と取引所は述べています。

Nakamao, however, disputed Binance's assessment, alleging that the exchange had been aware of the malicious plugin for some time and had even encouraged a key opinion leader (KOL) to gather more information from the hacker.

しかし、ナカマオ氏はバイナンスの評価に異議を唱え、バイナンスは以前からこの悪意のあるプラグインを認識しており、キーオピニオンリーダー(KOL)にハッカーからより多くの情報を収集するよう奨励していたと主張した。

On her part, Yi He warned users about the dangers of logging into accounts with active cookie plugins to avoid the inconvenience of typing their passwords each time. “Binance is not able to compensate users when their own login devices are compromised,” she stated.

Yi He 氏は、毎回パスワードを入力する煩わしさを避けるために、有効な Cookie プラグインを使用してアカウントにログインすることの危険性についてユーザーに警告しました。 「バイナンスは、ユーザー自身のログインデバイスが侵害された場合にユーザーを補償することはできません」と彼女は述べた。

オリジナルソース:9c86bd134dbfaf57b34b1517068be768

免責事項:info@kdj.com

提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。

このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

2026年07月26日 に掲載されたその他の記事